INDIA - Senior Security Incident Responder
Listed on 2026-09-02
-
IT/Tech
Cybersecurity, Security Management & Operations, Information Security & Data Protection
Senior Security Incident Responder
Required
Skills & Experience:
• Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or related field.
• 10+ years of experience in cybersecurity, including significant experience in Security Operations Center (SOC) and Incident Response functions.
• Proven experience leading investigations of major cybersecurity incidents and security breaches.
• Strong understanding of incident response methodologies, attacker tactics, and forensic investigation techniques.
• Experience working in enterprise or global environments with complex security infrastructures.
• Ability to coordinate technical and non-technical stakeholders during high-pressure incident situations.
• Experience working in one of the SIEM platforms (Microsoft Sentinel, Splunk, QRadar, Elastic, Log Rhythm, etc.)
• Experience working in one of the Endpoint Detection and Response platforms (Microsoft Defender, Crowd Strike, Sentinel One, Carbon Black, etc.)
• Experience with query languages and scripting (KQL, SPL, Python, Power Shell, Bash/Shell scripting)
• Experience with API integrations and workflow automations
Nice to Have
Skills & Experience:
• Preferred
Certifications:
o GIAC Certified Incident Handler (GCIH)
o GIAC Certified Forensic Analyst (GCFA)
o GIAC Certified Enterprise Defender (GCED)
o CISSP
o Certified SOC Analyst (CSA)
o Microsoft Security Operations Analyst Associate
o SANS Incident Response training or equivalent
Job Description:
We are seeking a Senior Security Incident Responder who will be responsible for leading the investigation, containment, eradication, and recovery of cybersecurity incidents across the enterprise. This role serves as a technical leader during major security incidents, leveraging security monitoring tools, threat intelligence, forensic techniques, and advanced analytics to determine attack scope, impact, root cause, and remediation actions.
The role requires strong expertise in security operations, incident response, threat detection, log analysis, and security tooling, as well as the ability to coordinate response activities across technical teams, business stakeholders, legal, privacy, compliance, and third-party vendors. The individual will also drive continuous improvement of SOC capabilities through playbook development, automation, detection tuning, and response orchestration.
• Lead the investigation and response of major cybersecurity incidents, including ransomware, phishing, insider threats, malware, credential compromise, and data breaches.
• Perform incident triage, analysis, containment, eradication, recovery, and post-incident activities.
• Conduct root cause and impact analysis to identify attack vectors, affected systems, and business impact.
• Analyze security alerts, logs, network traffic, endpoint telemetry, cloud activity, and threat intelligence to determine the scope of incidents.
• Utilize SIEM, EDR, NDR, cloud security, email security, and identity security tools to investigate and respond to security events.
• Correlate data from multiple security technologies to identify malicious activity, reconstruct attack timelines, and uncover threat actor behavior.
• Perform threat hunting activities and identify indicators of compromise (IOCs), attacker tactics, techniques, and procedures (TTPs).
• Serve as the technical lead during major incidents and coordinate response efforts across cybersecurity, infrastructure, cloud, application, legal, privacy, compliance, and business teams.
• Provide clear incident communications, status updates, executive briefings, and ensure proper documentation and regulatory reporting.
• Develop, maintain, and optimize incident response playbooks, runbooks, and standard operating procedures.
• Design and implement automation and SOAR workflows to improve investigation efficiency, response consistency, and SOC effectiveness.
• Create and improve detection rules, use cases, and response processes while driving continuous improvements through lessons learned, threat intelligence, and incident trend analysis.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).